CVE-2016-5299

Description

A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.822

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox (50.0)Windows
Update for Mozilla Firefox x64 (50.0)Windows
Update for Mozilla Firefox (50.0.1)Windows
Update for Mozilla Firefox x64 (50.0.1)Windows
Update for Mozilla Firefox (50.0.2)Windows
Update for Mozilla Firefox x64 (50.0.2)Windows
Update for Mozilla Firefox (50.1.0)Windows
Update for Mozilla Firefox x64 (50.1.0)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304314Update for Mozilla Firefox x64 (50.0)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304365Update for Mozilla Firefox x64 (50.0.1)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304376Update for Mozilla Firefox x64 (50.0.2)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-304411Update for Mozilla Firefox x64 (50.1.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234